The Bonzo Lend lending protocol, deployed on the Hedera ecosystem, fell victim to a sophisticated price oracle attack. The attacker managed to withdraw assets worth approximately $9 million by exploiting a vulnerability in the third-party data provider Supra, rather than in the platform's own smart contracts.
According to the analysis conducted, the attacker deposited only 250 SAUCE tokens as collateral. They then fed a fake asset price to the oracle, artificially inflating it by roughly a trillion times. This manipulation allowed them to borrow colossal sums — about 6.6 million USDC and 34.5 million wHBAR — with virtually zero real collateral. In essence, the attacker "printed" themselves a credit line using the fictitious value of a minuscule deposit.
The Bonzo Finance team promptly suspended the lending service and the points accrual program. Developers emphasize that the incident is solely related to an error in the price verification system of the Supra oracle provider, not to vulnerabilities in the protocol's own code. This is a classic example of an attack on a "weak bridge" in DeFi — a third-party infrastructure element that can become an entry point even with flawless smart contract architecture.
Currently, Bonzo Lend is collaborating with partners in the Hedera ecosystem for a detailed analysis of the incident and to develop a plan for fund recovery. Notably, one of the addresses involved in withdrawing about $1 million during the window of the anomalous SAUCE price identified itself as a "white hat hacker" and stated its intention to return the assets. This offers hope for partial compensation of the damages.
Expert opinion: The attack on Bonzo Lend is yet another alarming signal for the entire DeFi industry. The problem lies not in the protocol's code, but in its dependence on third-party oracles. Until projects begin implementing decentralized and repeatedly verified data sources with mechanisms to protect against manipulation, such incidents will recur. The loss of $9 million due to a single fictitious price is not a coincidence, but a systemic risk that requires an immediate revision of security standards.